Job Summary
This role requires a highly motivated IAM specialist with strong expertise in Saviynt and SAP Access Security. The Specialist will contribute across two primary domains: access automation through system integrations and role-based access control (RBAC) design, build, and validation. Successful execution of this role requires close collaboration with business, project, and IT teams to deliver secure, compliant, and scalable access solutions.
This is an individual contributor role focused on ensuring the effectiveness, accuracy, and sustainability of access management automation and RBAC capabilities. The Specialist acts as a trusted subject matter expert, leading hands-on design and execution activities, validating outcomes, supporting project delivery, and actively sharing knowledge with project and operational teams.
Main Responsibilities
Access Automation Integrations
oServe as a trusted authority on Saviynt IGA functionality, configuration, and enterprise integrations, providing guidance to technical and business stakeholders.
oDesign and monitor high‑quality integrations between Saviynt and systems including ServiceNow, Active Directory, SaaS and PaaS applications, and on‑premise target systems.
oConfigure, maintain, and enhance identity integrations between SaaS/PaaS applications and SAP Cloud Identity Services, ensuring secure and reliable data flows.
oOversee execution and be a subject matter expert for the following,
oIdentity personas and identity-related data across connected systems (create, update, decommission)
oIntegrations with Active Directory, enterprise portals, RPA solutions, MFA, and SSO platforms
oOnboarding and integration of new target systems (cloud and on‑prem), to ensure integration patterns are secure, scalable, and compliant
oSupport user lifecycle management processes, including joiner, mover, and leaver (JML) workflows and automation.
oSaviynt Risk and Compliance capabilities, including Segregation of Duties (SoD) analysis, Critical Action monitoring, access certifications, and audit evidence generation.
oDirect and participate in unit testing, and support end-to-end functional validation of integrations and automation workflows.
SAP Access Security
oDesign, build, unit test, and deploy SAP roles, translating functional business requirements into security technical role designs.
oDemonstrate comprehensive knowledge of various SAP security role types and authorization concepts.
oPossess hands-on experience with SAP Fiori Spaces and Pages.
oUtilize SAP Change Request Management (ChaRM) to manage security transports across SAP landscapes.
oSupport security role design, modification, and lifecycle maintenance across multiple SAP platforms, modules, and SaaS and PaaS applications, including:
oSAP Analytics Cloud
oSAP Business Technology Platform (BTP)
oSAP Cloud ALM
oSAP Cloud Identity Services
oSAP Datasphere
oSAP Enable Now
oSAP HANA Databases
oSAP Integrated Business Planning (IBP)
oSAP Signavio
oVertex
oDemonstrate a strong understanding user provisioning process in multiple SAP platforms and SaaS and PaaS applications, perform manual user provisioning steps when automated solutions are unavailable.
oEnsure SAP roles are free of unmitigated segregation of duties conflicts or critical action risks and align with least-privilege principle.
oTroubleshoot access issues, analyze authorization failures, and resolve security conflicts.
oProvide application security support for both on-premises SAP environments and SAP RISE solutions.
oParticipate in testing cycles to validate access changes, role updates, and remediation activities.
oPossess hands-on experience with SAP Cloud Identity Services, including user authentication and user provisioning for SaaS and PaaS applications.
Communications, Collaboration and Support
oCollaborate closely with technical, functional, data, risk, and control teams across SAP and IAM initiatives.
oCommunicate effectively with both technical and non‑technical stakeholders, clearly explaining security concepts, design decisions, and recommendations.
oManage incoming requirements, competing priorities, and deadlines using strong organizational and planning skills.
oProvide regular status updates, identify risks and roadblocks, and propose mitigation strategies.
oSupport end‑user acceptance testing (UAT) and regression testing activities.
oMaintain current process documentation, control narratives, and audit evidence for assigned IAM controls.
oContribute to the continuous improvement of IAM compliance procedures, templates, validation checklists, and operational standards.
oPromote knowledge sharing within the IAM team to strengthen audit readiness and control maturity.
Working Conditions
The role operates under standard office working conditions, with a regular 8 hour day ( – 5pm EST), and workweek from Monday to Friday. Due to the nature of the responsibilities, the incumbent must be able to meet tight deadlines, manage competing priorities, engage with multiple stakeholders and leaders, and work effectively under pressure. Minimal travel may be required (up to 10%) within Canada. Holidays follow Quebec statutory standards.
Requirements
Experience
oMinimum 5 - 7 years of experience in Identity & Access Management, Application Security, IAM Integrations and SAP Cloud Identity Services
oMinimum 5 years of experience in SAP Application role design
oExperience with SAP Migrations (Greenfield and Brownfield) as well as RISE Migrations a plus
Education/Certification/Designation
oBachelor’s Degree in Computer Science, Information Systems, or an equivalent combination of education and relevant work experience.
Competencies
oAdapt to evolving requirements and unexpected challenges within a fast‑paced SAP program environment.
oCommunicates with impact across diverse audiences.
oDemonstrates accountability and ownership for deliverables.
oExercises sound judgment in identifying, managing, and escalating risks.
oResults‑oriented, with a strong focus on quality and timely delivery.
oAbility to manage multiple concurrent assignments of moderate complexity.
oStrong problem‑solving skills, applying ingenuity and creativity.
oDetail‑oriented with a strong quality mindset.
oProduces clear, concise documentation tailored to various audiences.
oStrong time management, prioritization, and organizational skills.
oAble to think and act decisively under pressure.
oWorks effectively with limited supervision while demonstrating a sense of urgency.
oCapable of resolving complex security issues through research and technical investigation.
oDemonstrates strong teamwork and collaboration skills, adapting communication style as needed.
Technical Skills/Knowledge
oApplication security knowledge across SAP ABAP and Fiori, SAP Cloud Applications, SAP Cloud Identity Services, SAP HANA, and SAP RISE environments.
Strong functional and integration knowledge of Saviynt.
oIntegration experience with ServiceNow, Active Directory, enterprise portals, RPA solutions, MFA, and SSO platforms
oExperience integrating SAP systems with third‑party applications.
oSolid understanding of SOX requirements, ITGC frameworks, and audit methodologies related to access management.
oKnowledge of IAM processes, including user lifecycle management, provisioning, deprovisioning, and recertification.
oFamiliarity with IAM tools, enterprise systems, and access governance principles.
oStrong analytical skills to identify, assess, and mitigate security risks.